US2025310221A1PendingUtilityA1

Lightweight container networking solution for resource constrained devices

Assignee: RED HAT INCPriority: Nov 16, 2022Filed: Jun 12, 2025Published: Oct 2, 2025
Est. expiryNov 16, 2042(~16.3 yrs left)· nominal 20-yr term from priority
H04L 67/60H04L 43/028
65
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A networking request is received from a first workload, within a first container, on an edge device. A determination is made that the destination of the networking request is a second workload, within a second container, on the edge device. In response to determining the destination of the networking request, the networking request is forwarded to the second application, wherein the forwarding comprises intercepting the networking request at a socket associated with the first workload and delivering the network request to a socket associated with the second workload.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method comprising:
 receiving a networking request from a first workload executing within a first container on an edge device;   determining that a destination of the networking request is a second workload executing within a second container on the edge device;   determining that the destination of the networking request is permitted by an access list; and   forwarding the networking request to the second workload at a socket layer.   
     
     
         2 . The method of  claim 1 , wherein the access list is associated with a network policy, and wherein the access list serves as a private firewall within the edge device. 
     
     
         3 . The method of  claim 1 , wherein the networking request comprises a networking system call, and wherein forwarding the networking request comprises forwarding a payload of the networking system call. 
     
     
         4 . The method of  claim 1 , wherein determining the destination of the networking request comprises querying a map. 
     
     
         5 . The method of  claim 1 , wherein the forwarding comprises:
 intercepting the networking request at a first socket associated with the first workload; and   delivering the networking request to a second socket associated with the second workload.   
     
     
         6 . The method of  claim 5 , wherein intercepting the network request comprises obtaining a payload of the network request prior to encapsulating the payload within a TCP/IP packet. 
     
     
         7 . The method of  claim 5 , wherein intercepting the network request comprises executing an extended Berkeley packet filter. 
     
     
         8 . A system comprising:
 a memory; and   a processing device operatively coupled to the memory, the processing device to:
 receive a networking request from a first workload executing within a first container on an edge device; 
 determine that a destination of the networking request is a second workload executing within a second container on the edge device; and 
 forward the networking request to the second workload at a socket layer. 
   
     
     
         9 . The system of  claim 8 , wherein the networking request comprises a networking system call. 
     
     
         10 . The system of  claim 9 , wherein, to forward the networking request, the processing device is to forward a payload of the networking system call. 
     
     
         11 . The system of  claim 8 , wherein, to forward the networking request to the second workload, the processing device is to:
 intercept the networking request at a first socket associated with the first workload; and   deliver the networking request to a second socket associated with the second workload.   
     
     
         12 . The system of  claim 11 , wherein, to intercept the networking request, the processing device is to obtain a payload of the network request prior to encapsulating the payload within a TCP/IP packet. 
     
     
         13 . The system of  claim 11 , wherein, to intercept the networking request, the processing device is to execute an extended Berkeley packet filter. 
     
     
         14 . The system of  claim 8 , wherein, to determine that the destination of the networking request is a second workload, the processing device is to query a map. 
     
     
         15 . A non-transitory computer-readable medium having instructions stored thereon which, when executed by a processing device, cause the processing device to:
 receive a networking request from a first workload executing within a first container on an edge device;   determine that a destination of the networking request is a second workload executing within a second container on the edge device;   determine that the destination of the networking request is permitted by an access list; and   forward the networking request to the second workload at a socket layer.   
     
     
         16 . The non-transitory computer-readable medium of  claim 15 , wherein the access list is associated with a network policy. 
     
     
         17 . The non-transitory computer-readable medium of  claim 15 , wherein the access list serves as a private firewall within the edge device. 
     
     
         18 . The non-transitory computer-readable medium of  claim 15 , wherein the networking request comprises a networking system call, and wherein, to forward the networking request, the instructions cause the processing device to forward a payload of the networking system call. 
     
     
         19 . The non-transitory computer-readable medium of  claim 12 , wherein, to determine the destination of the networking request, the instructions cause the processing device to query a map. 
     
     
         20 . The non-transitory computer-readable medium of  claim 12 , wherein, to forward the networking request to the second workload, the instructions cause the processing device to:
 intercept the networking request at a first socket associated with the first workload; and   deliver the networking request to a second socket associated with the second workload.

Join the waitlist — get patent alerts

Track US2025310221A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.